Legal
Privacy policy
Draft of
Who this is from
The JetSet Group Inc. (“JetSet”, “we”), [ADDRESS], is responsible for the personal data described here. Questions about it: [CONTACT EMAIL].
Travellers are in the EU, the UK and elsewhere. We apply the same rights to everyone, wherever you are: to see your data, to delete it, and to say no to marketing and analytics.
For counselConfirm who the controller is, which law governs ([JURISDICTION]) and whether a representative or a data protection officer is needed.
In short
- JetSet never holds your secret keys or your funds. Your keys are made on your phone and stay there.
- We keep an account, not a balance. It holds your verified email and phone and a few profile details, and links your wallet’s public keys to it. Your balance and your payments are on the Stellar ledger, which your wallet reads directly.
- Marketing and analytics are opt-in, one by one. Each choice is recorded with the time you made it, and you can withdraw it.
- You can download your data and delete your account. A few records have to stay afterwards; they are listed below.
What we collect
What the product needs to work, and what you agree to on top.
- Your account. Your email address and phone number (both verified), your name, avatar and language, when each was created or verified, and your consent choices with the time you made each one.
- Your wallet’s public keys. The Stellar public keys you link to your account, with a label for the device and when each was linked or revoked. Public keys only.
- Your receipts. When you pay a vendor, the vendor’s till writes a receipt: what you bought, the tip, the fee, the currency and a reference, filed under the payment’s transaction hash. That is how your wallet can show what you bought and not only an amount. After a payment, the wallet proves its key to the JetSet account service so the receipt can load without a second prompt.
- Address lookups. When you open a bill, look at a payment you made at a till, or type an address to send to, the wallet asks the JetSet service who that public address belongs to, and sends only the address.
- Disputes you raise.
- If you run a business on JetSet, its profile, its staff (accounts with a role: owner, manager or till), its terminals (each with its merchant Stellar public key), its payout destinations and its disputes. [PAYOUT DESTINATION: what one holds.]
- Sponsorship records. JetSet pays your Stellar account’s starting deposit and the network fee for your payments, and keeps a record of which accounts it sponsored and what it spent.
- Product analytics, only if you agree. City, venue, category, spend, device, language and how you found JetSet.
- An access log. Each time JetSet’s own systems read personal data, a line is added to a log that cannot be edited or deleted: when, which part of the system, why, and which kinds of record. It never contains the values themselves.
For counselThe two wallet requests added under receipts and address lookups (JET-93, JET-123): what JetSet’s service records when it answers them, and for how long, is not stated here. “Proves its key” should be read against “What we never hold”: confirm the wording says the secret key is never sent.
Payments themselves are on Stellar, a public ledger. Anyone can see that one address paid another, and how much. JetSet did not create that record and cannot change or remove it.
What we never hold
- Secret keys. They live in your phone’s secure storage, behind Face ID or your phone’s biometrics. JetSet never sees them.
- Balances and transactions. The ledger is the record, and your wallet reads it directly.
- Identity documents. JetSet does not collect them.
- Passwords. You sign in with an email link.
For counselPasskeys are planned for a later release (Decision 003 puts them first, with the email link as the fallback) but are not built. When they ship, this line and any description of sign-in need updating.
What we use it for, and your choices
We use your data to run JetSet: to keep your account, to link your wallet’s keys to it, to show your receipts, and to sponsor your account and its payments on Stellar.
Three further uses each need your agreement, separately: marketing email, marketing SMS and product analytics. Each choice is explicit and recorded with the time you made it, and you can withdraw it at any time. Marketing follows your choices. Withdrawing product analytics stops new events at once.
For counselThe legal basis for each use. What should happen to analytics events collected before consent is withdrawn: today they are kept (data-rights design, question 2).
For counselConfirm where in the app a person changes these choices. The identity API offers it; the wallet’s use of it is not yet verified.
Your rights
See your data. You can download one file, in JSON, with everything your account owns: your profile and consents and the history of every change to them, your wallet’s public keys, the receipts of payments you made, disputes you raised, your vendor memberships, sponsorship records for your accounts, your analytics events, and the log entries about when our systems read your data. It leaves out your sign-in credentials (held by the sign-in provider), receipts you handled as a vendor’s staff (they belong to the vendor) and the public ledger.
Delete your account. “Delete my account” really deletes. We remove your account and sign-in, the links to your wallet keys, your staff memberships, your analytics events, the disputes you raised and the record of your consent choices. Because it cannot be undone, we ask you to type a confirmation and to have signed in within the last 15 minutes. It is refused while you are the last owner of a vendor: transfer ownership, or delete the vendor, first.
For counselWhether proof of consent may outlive an account, and for how long (data-rights design, question 1). The record of your consent choices is listed above as removed, because that is what the account does today; if counsel decides it must stay, it moves to the list below.
What stays after deletion, and why.
- Receipts of payments you made stay in the vendor’s books, with the pseudonymous key of the wallet that paid. After deletion nothing of ours ties that key to a person.
- Sponsorship records stay for JetSet’s own accounting, no longer linked to you.
- The log of when our systems read your data stays, for accountability. It holds no values.
- Your Stellar account and its transactions stay. A public ledger cannot be edited by anyone, JetSet included, and the deposit JetSet put up to open your account stays locked in it.
- Backups age out on the hosting provider’s schedule.
For counselHow long the access log is kept, and whether its pseudonymous subject id may stay after erasure (question 3). Whether the pseudonymous payer key in a receipt is acceptable after erasure (question 4). What backups need (question 5).
Withdraw a choice. Change any of the three choices above whenever you like.
How we know it is you. You must be signed in to ask for your data, and signed in recently to delete it.
For counselWhether that is enough proof of identity for an access or an erasure request (data-rights design, question 6).
Complain. You can complain to a data protection authority. [JURISDICTION: which one.]
Who else handles your data
- Supabase hosts JetSet’s database and sign-in.
- The Stellar network is public and is not a service we run. What is on it, we cannot change or remove.
- [PROCESSORS: email and SMS delivery, the app stores, the website host and any analytics service. The decisions leave self-hosted analytics open. Name each before launch.]
How long we keep it
Your account, and what hangs off it, is kept until you delete your account. Deleting is immediate: there is no grace period. What stays afterwards, and why, is listed under Your rights.
For counselHow long each kind of data is kept, and whether deletion should have a grace period (the data-rights design built “immediately” as a default that Amar has yet to confirm).
How it is protected
Database rules mean each person can read only their own records. Service keys stay in JetSet’s backend, and every time our own systems read personal data, an entry is added to the access log. Your secret keys never reach us. [HOSTING: encryption at rest and backups are properties of the host, to be described once hosting is chosen.]
This website
This website sets no cookies, loads nothing from other websites and runs no analytics.
Two of its pages handle links into the app: /pay/… for a payment and /auth/callback for signing in. Those links can carry a till address, a bill or a one-time sign-in code in the address. The pages do not store it or send it anywhere else; they pass it to the JetSet app on your device. Like any web request, the address does reach the site’s host. [HOSTING: its logs, how long they are kept and where, once hosting is chosen.]
Changes and contact
For counselChildren, how changes to this policy are announced, and the date it takes effect.
The JetSet Group Inc., [ADDRESS], [CONTACT EMAIL].